cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data

cPanel has released patches for CVE-2026-68490, a vulnerability related to incorrect permissions in its CalDAV/CardDAV implementation. This flaw could allow a local user on a shared server to access calendar events and contacts from other hosting accounts. The issue affects cPanel/WHM version 120 and later, highlighting the risks associated with tenant isolation in shared-hosting environments. […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: